6 ms·
" # Server Code Injection # # Strings which can cause user to run code on server as a privileged user (c.f. https://news.ycombinator.com/item?id=7665153 https:/
by jsat 11y ago
"
# Server Code Injection
#
# Strings which can cause user to run code on server as a privileged user (c.f. https://news.ycombinator.com/item?id=7665153 https://news.ycombinator.com/item?id=7665153)
/dev/null; rm -rf /*; echo
"
That's a little aggressive for testing no?
- jleader 11y agoSome would argue that if you're testing on a system you can't recreate easily/quickly, you're doing devops wrong.
- xtreme 11y agoThe problem is not restoring the system, but the time lost in figuring out what caused it without any logs.
- pavel_lishin 11y agoAnd I'd agree, but this would be a pretty disproportionate punishment for the crime of doing devops wrong :P
- DonHopkins 11y agoIt's two crimes: doing devops wrong, and having a huge security hole.
- rattray 11y agoA lot of people do devops wrong... and I don't want to make those people even more scared to test things.
- minimaxir 11y agoAccepted a pull request which is nicer.
- cowls 11y agoLikewise: 1;DROP TABLE users 1'; DROP TABLE users-- Seems a bit hairy to have that in there in case someone tries to run these tests on their prod environment
- MertsA 11y agoit also won't work as most systems are going to require --no-preserve-root for that to do anything.